content, and pursue the availability of accurate registration data by continuing to engage with
the Internet Corporation for Assigned Names and Numbers (ICANN) and other stakeholders
in the internet governance system, notably through the Public Safety Working Group of
ICANN’s Governmental Advisory Committee. The proposal in the revised NIS Directive
accordingly envisages the maintaining of accurate and complete databases of domain names
and registration data, or ‘WHOIS data’, and providing lawful access to such data as essential
to ensuring the security, stability and resilience of the DNS.
The Commission will also continue to work to provide appropriate channels and clarify rules
to obtain cross-border access to electronic evidence for criminal investigations (needed in
85% of investigations, with 65% of the total requests going to providers based in another
jurisdiction), by facilitating the adoption and subsequent implementation of the ‘e-evidence
package’ and practical measures80. The swift adoption by the European Parliament and
Council of the e-evidence proposals is key to provide practitioners with an efficient tool.
Electronic evidence must be readable, thus the Commission will further work on the support
to law enforcement capacity in the area of digital investigations, including dealing with
encryption when encountered in criminal investigations while fully preserving its function to
protect fundamental rights and cybersecurity.
2.3
EU cyber diplomacy toolbox
The EU has been using its cyber diplomacy toolbox81 to prevent, discourage, deter and
respond to malicious cyber activities. After introducing the legal framework for targeted
restrictive measures against cyber-attacks in May 201982, the EU listed six individuals and
three entities responsible for, or involved in, cyber-attacks affecting the EU and its Member
States under the regime in July 202083. Another two individuals and one body were listed in
October 202084. Malicious cyber activities, including those of a slow-burning nature, should
be tackled by an effective and comprehensive joint EU diplomatic response, using the full
range of measures available at EU level.
80
COM(2018) 225 and 226; C(2020) 2779 final. In particular, the SIRIUS project recently received additional
funding under the Partnership Instrument to improve channels to obtain lawful cross-border access to electronic
evidence for criminal investigations (needed in 85% of investigations into serious crimes, with 65% of the total
requests going to providers based in another jurisdiction), and establishing compatible rules at international
level.
81
https://www.consilium.europa.eu/en/press/press-releases/2017/06/19/cyber-diplomacy-toolbox/
82
Council Decision (CFSP) 2019/797 of 17 May 2019 concerning restrictive measures against cyber-attacks
threatening the Union or its Member States (OJ L 129I 17.5.2019, p. 13); and Council Regulation (EU)
2019/796
of 17 May 2019 concerning restrictive measures against cyber-attacks threatening the Union or its Member
States (OJ L 129I 17.5.2019, p. 1) 1)
83
Council Decision (CFSP) 2020/1127 of 30 July 2020 amending Decision (CFSP) 2019/797 concerning
restrictive measures against cyber-attacks threatening the Union or its Member States (ST/9564/2020/INIT) (OJ
L 246, 30.7.2020, p. 12–17); and Council Implementing Regulation (EU) 2020/1125 of 30 July 2020
implementing Regulation (EU) 2019/796 concerning restrictive measures against cyber-attacks threatening the
Union or its Member States (ST/9568/2020/INIT) (OJ L 246, 30.7.2020, p. 4–9).
84
Council Decision (CFSP) 2020/1537 of 22 October 2020 amending Decision (CFSP) 2019/797 concerning
restrictive measures against cyber-attacks threatening the Union or its Member States (OJ L 351I , 22.10.2020,
p. 5–7); and Council Implementing Regulation (EU) 2020/1536 of 22 October 2020 of implementing Regulation
(EU) 2019/796 concerning restrictive measures against cyber-attacks threatening the Union or its Member States
(OJ L 351I, 22.10.2020, p. 1–4).
16